Usable with caveats: it has a stable release history, a matching source repository, and a recent release, but maintenance evidence is thin. Zero commits in the last three months, no tests or security policy, and a very small maintainer and user base increase the risk of slow support.
67%
Total Score
50
100
88
83
Only one registry account has publish access. A single publisher is not itself proof of poor maintenance, but combined with zero recent commits it increases the risk that support depends on one person.
The registry namespace and repository owner correspond to the same project identity, but the repository owner is a user rather than an organization. This supports basic ownership consistency while leaving a relatively small backing structure.
There were no commits and no active maintainers in the last three months. Although the package had a release about 8 months ago, the lack of recent repository work raises maintenance and abandonment concerns.
The repository has zero stars and forks and only two watchers. Popularity is not required for a small package, but these counters provide little independent evidence of broad review or community support.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured. This leaves a modest transparency and detection gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
illuminate/support Version ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.